Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-48581

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Surface Broker SDMA Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

FAQ

What privileges could be gained by an attacker who successfully exploited this vulnerability?

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

What actions do customers need to perform to be protected against this vulnerability?

Surface devices get updates through Windows Update. See Surface update history for more information.

If you wish to install the updates manually, you can do the following:

  1. In the Surface app, expand Help & support to check the update status.
  2. If there are updates available, select the Check for updates button to open Windows Update and install the available updates.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 12%
0.00214
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
18 дней назад

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
github
18 дней назад

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
fstec
19 дней назад

Уязвимость микропрограммного обеспечения сенсорных дисплеев Microsoft Surface, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 12%
0.00214
Низкий

7.8 High

CVSS3